cve-2022-44877
CRITICAL CVSS 9.8 cisa_known_exploited
Description
CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command injection vulnerability that allows remote attackers to execute commands via shell metacharacters in the login parameter.
Timeline
- Published
- 2023-01-17
- Last Modified
- 2023-01-17
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cvss": 9.8,
"datePublished": "2023-01-17",
"dateUpdated": "2023-01-17",
"description": "CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command injection vulnerability that allows remote attackers to execute commands via shell metacharacters in the login parameter.",
"dueDate": "2023-02-07",
"id": "CVE-2022-44877",
"kev_catalogs": [
"cisa"
],
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://control-webpanel.com/changelog#1669855527714-450fb335-6194; https://nvd.nist.gov/vuln/detail/CVE-2022-44877",
"product": "Control Web Panel",
"requiredAction": "Apply updates per vendor instructions.",
"severity": "CRITICAL",
"source": "cisa_known_exploited",
"title": "CWP Control Web Panel OS Command Injection Vulnerability",
"vendor": "CWP"
}
Enrichment data
Aggregated bundle (all enrichments)